OAuth Finds the SaaS Employees Sign Into. Our Chrome Extension Finds the Rest.
OAuth discovery surfaces every app authorized through Sign in with Google or Microsoft, with exact scopes. It cannot see the tools people sign up for with a work email and a password. Our new browser extension closes that gap, privacy first.
MCP Governance: How to Control What AI Agents Can Do in Your SaaS
AI agents now reach your SaaS through the Model Context Protocol. MCP governance is how you decide what they're allowed to do, prove what they did, and shut them off in seconds. What it is, why API keys aren't enough, the MCP gateway pattern, and a checklist.
Shadow AI: 80% of Your Employees Use It. You Approved 23%.
Shadow AI is shadow IT that reads your data and acts on your systems. Employees adopt AI faster than security can review it, and the newest tools take actions, not just answer questions. Why it spreads, what it costs, and how to govern it.
When the Employee Leaves but the Agent Stays
AI agents built by departing employees keep running after their creator's account is disabled. They still have access. Nobody owns them. Here is what to do about it.
How to Connect Claude to Slack via MCP with Access Controls
Step-by-step: install the Lutril MCP server, define a Slack access policy, register the agent, and test it. Policy-checked tool calls, a full audit trail, and a kill switch from the start.
Okta, Azure AD, and Lutril: Who Manages Access When AI Agents Enter the Picture?
Okta and Azure AD are excellent at managing human identity. Neither was designed for AI agents. Here is where each fits, where the gaps are, and why you probably need all three.
What Is the Access Layer for AI Agents?
AI agents need identity, policy enforcement, audit logs, and a kill switch before they touch your SaaS stack. That infrastructure has a name. Here is what it is and how it works.
Your IT Team Knows About 40 SaaS Apps. You Have 130.
Shadow IT is not a policy failure. It is the natural result of frictionless SaaS adoption. Here is why it keeps growing, what risk it creates, and what to do beyond writing a policy nobody reads.
Disabling an Okta Account Is Not Offboarding
41% of employees keep access to company systems after leaving. Most of that access sits in SaaS tools your IdP never touched. Here is what complete access revocation actually requires.
SOC 2 Wants Proof.
Not a Spreadsheet.
Most access reviews are a formality. Managers approve without context, shadow IT goes unreviewed, and evidence is thin. Here is what SOC 2 and ISO 27001 actually require, and what closing the gap looks like.
The AI Governance Gap
Your security stack controls who can access your SaaS tools. It has no idea your AI agents even exist. The problem, the three gaps, and what governance for agents actually looks like.